angusfaaan
Newbie
- Registriert
- Sep. 2011
- Beiträge
- 2
Hallo,
ich glaube das Thema wurde hier schon x-mal angeschnitten, aber irgendwie hab ich noch keine Problemlösung für mich gefunden.
Bin auch kein PC-Freak, sodass ich froh bin, jetzt endlich mal es geschafft zu haben die Minidump-Datei auszulesen:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\090511-22994-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02a52000 PsLoadedModuleList = 0xfffff800`02c97670
Debug session time: Mon Sep 5 17:34:01.197 2011 (UTC + 2:00)
System Uptime: 0 days 0:05:10.054
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 30, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+46485 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000030
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: mscorsvw.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff880027dc6e0 -- (.trap 0xfffff880027dc6e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002bacbc5 rsp=fffff880027dc870 rbp=fffff880027dc8c0
r8=fffff80002a52000 r9=0000000000000001 r10=0000058000000000
r11=0000000fffffffff r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po nc
nt!MiResolvePageFileFault+0x1115:
fffff800`02bacbc5 8b4830 mov ecx,dword ptr [rax+30h] ds:00000000`00000030=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002a61d7e to fffff80002acec40
STACK_TEXT:
fffff880`027dc578 fffff800`02a61d7e : 00000000`0000001a 00000000`00041287 00000000`00000030 00000000`00000000 : nt!KeBugCheckEx
fffff880`027dc580 fffff800`02accd6e : 00000000`00000000 00000000`00000030 fffffa80`0684f800 00000000`21d00000 : nt! ?? ::FNODOBFM::`string'+0x46485
fffff880`027dc6e0 fffff800`02bacbc5 : 00000000`00001018 00000000`00000000 fffff8a0`088f0af8 fffff800`02afffaf : nt!KiPageFault+0x16e
fffff880`027dc870 fffff800`02b416b0 : 000007fe`f60143c6 fffff683`ff7b00a0 fffffa80`03d1eb08 fffffa80`03d1eb11 : nt!MiResolvePageFileFault+0x1115
fffff880`027dc9b0 fffff800`02adbf19 : 00000000`00000000 ffffffff`ffffffff 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x399d4
fffff880`027dcac0 fffff800`02accd6e : 00000000`00000000 000007fe`f60143c6 000007ff`011c3201 00000000`0000000c : nt!MmAccessFault+0x359
fffff880`027dcc20 00000000`77028fe4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`001cba20 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77028fe4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+46485
fffff800`02a61d7e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+46485
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
Followup: MachineOwner
---------
Bin für jeden Tipp sehr dankbar!!
ich glaube das Thema wurde hier schon x-mal angeschnitten, aber irgendwie hab ich noch keine Problemlösung für mich gefunden.
Bin auch kein PC-Freak, sodass ich froh bin, jetzt endlich mal es geschafft zu haben die Minidump-Datei auszulesen:
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\090511-22994-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02a52000 PsLoadedModuleList = 0xfffff800`02c97670
Debug session time: Mon Sep 5 17:34:01.197 2011 (UTC + 2:00)
System Uptime: 0 days 0:05:10.054
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 30, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+46485 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000030
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: mscorsvw.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff880027dc6e0 -- (.trap 0xfffff880027dc6e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002bacbc5 rsp=fffff880027dc870 rbp=fffff880027dc8c0
r8=fffff80002a52000 r9=0000000000000001 r10=0000058000000000
r11=0000000fffffffff r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po nc
nt!MiResolvePageFileFault+0x1115:
fffff800`02bacbc5 8b4830 mov ecx,dword ptr [rax+30h] ds:00000000`00000030=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002a61d7e to fffff80002acec40
STACK_TEXT:
fffff880`027dc578 fffff800`02a61d7e : 00000000`0000001a 00000000`00041287 00000000`00000030 00000000`00000000 : nt!KeBugCheckEx
fffff880`027dc580 fffff800`02accd6e : 00000000`00000000 00000000`00000030 fffffa80`0684f800 00000000`21d00000 : nt! ?? ::FNODOBFM::`string'+0x46485
fffff880`027dc6e0 fffff800`02bacbc5 : 00000000`00001018 00000000`00000000 fffff8a0`088f0af8 fffff800`02afffaf : nt!KiPageFault+0x16e
fffff880`027dc870 fffff800`02b416b0 : 000007fe`f60143c6 fffff683`ff7b00a0 fffffa80`03d1eb08 fffffa80`03d1eb11 : nt!MiResolvePageFileFault+0x1115
fffff880`027dc9b0 fffff800`02adbf19 : 00000000`00000000 ffffffff`ffffffff 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x399d4
fffff880`027dcac0 fffff800`02accd6e : 00000000`00000000 000007fe`f60143c6 000007ff`011c3201 00000000`0000000c : nt!MmAccessFault+0x359
fffff880`027dcc20 00000000`77028fe4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`001cba20 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77028fe4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+46485
fffff800`02a61d7e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+46485
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+46485
Followup: MachineOwner
---------
Bin für jeden Tipp sehr dankbar!!